We release patches for security vulnerabilities for the latest major version of each SDK. Older versions may receive fixes on a best-effort basis.
| SDK | Version | Supported |
|---|---|---|
| Python | >= 1.x | ✅ Yes |
| Node.js | >= 1.x | ✅ Yes |
| Ruby | >= 1.x | ✅ Yes |
| Go | >= 1.x | ✅ Yes |
| PHP | >= 1.x | ✅ Yes |
| Java | >= 1.x | ✅ Yes |
| C# / .NET | >= 1.x | ✅ Yes |
Please do not report security vulnerabilities through public GitHub issues.
Instead, send an email to security@verifiedsms.com.
You should receive a response within 48 hours. If for some reason you do not, please follow up via the same channel.
- A clear description of the vulnerability
- Steps to reproduce (proof of concept code is helpful)
- The affected SDK and version
- Any potential impact you have identified
- We will acknowledge receipt of your report within 48 hours.
- We will investigate and determine the severity and impact.
- We will keep you informed as we work on a fix.
- Once a fix is ready, we will release a patch and publicly disclose the vulnerability with credit to you (unless you prefer to remain anonymous).
We prefer all communications to be in English.
When we receive a security bug report, we will:
- Confirm the problem and determine affected versions.
- Audit code to find any similar potential problems.
- Prepare fixes for all supported versions (see table above).
- Release new versions and update the affected SDKs.
- Publish a security advisory on GitHub and credit the reporter (if desired).
Thank you for helping keep VerifiedSMS and our users safe.